diff --git a/src/createApp.js b/src/createApp.js
index 165eca8df1d4c85e41c6fac4654eb56f83078df6..e6dcb3845a33d3d16c2a3674a4ec2cd6480f131e 100644
--- a/src/createApp.js
+++ b/src/createApp.js
@@ -66,7 +66,8 @@ export function createApp () {
   app.use(helmet({
     contentSecurityPolicy: false,
     crossOriginEmbedderPolicy: false,
-    originAgentCluster: false
+    originAgentCluster: false,
+    crossOriginOpenerPolicy: { policy: 'same-origin-allow-popups' }
   }))
   app.use('/healthy', health.LivenessEndpoint(healthCheck))
   app.use('/ready', health.ReadinessEndpoint(healthCheck))